The DOGE website is seemingly so insecure it can be edited by anyone

According to researchers, anyone who knows where to look can spray digital graffiti on the Department of Government Efficiency (DOGE) website. Two web development experts said the site doesn’t seem to be hosted on government servers and that the database it pulls from can be modified by those who locate it. At the time of writing, a message reading “these ‘experts’ left their database open - roro” is still visible on the DOGE site.

DOGE chief and President Trump consigliere Elon Musk said on Tuesday that his team would be as transparent as possible, with updates on its actions shared to an X account and website. As 404 Media notes, the DOGE website was pretty much blank at the time. Since then, it's been hurriedly assembled to show a feed of posts from the entity’s X account, along with details about the federal workforce.

The researchers told 404 that the site appeared to be built on Cloudflare Pages instead of government servers. After looking at the site’s architecture and API endpoints, one was able to locate the database containing stats on government employees. They made changes to database entries that were reflected on the DOGE website.

It's not the first time that a federal website operating under the Trump administration has appeared to have been slapped together. Just this week, the waste.gov was locked after it was reported that the site displayed a dummy WordPress page, complete with placeholder text.

DOGE does acknowledge that there are possible issues with its web presence. “This is DOGE's effort to create a comprehensive, government-wide org chart,” a footnote on the DOGE website reads. “This is an enormous effort, and there are likely some errors or omissions. We will continue to strive for maximum accuracy over time.”

However, it doesn’t exactly inspire confidence that a team tasked with making sweeping cuts to government spending and allegedly barging its way into federal systems that contain sensitive data on federal employees and citizens can’t secure its own website. Perhaps gutting the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency wasn't the wisest idea.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/the-doge-website-is-seemingly-so-insecure-it-can-be-edited-by-anyone-160612228.html?src=rss https://www.engadget.com/cybersecurity/the-doge-website-is-seemingly-so-insecure-it-can-be-edited-by-anyone-160612228.html?src=rss
Erstellt 10d | 14.02.2025, 17:20:25


Melden Sie sich an, um einen Kommentar hinzuzufügen

Andere Beiträge in dieser Gruppe

Apple reportedly plans to combine its modem with future processors as a single package

Apple introduced its first in-house cellular modem, the C1, last week with the announcement of

23.02.2025, 23:50:12 | Engadget
If you liked the Playdate game Root Bear, you should check out Pup Cup

You’ve heard of roguelike, you’ve heard of Soulslike, but have you ever heard of Rootlike?

23.02.2025, 21:40:05 | Engadget
Intuitive Machines is expected to launch its second lunar lander this week

Intuitive Machines, the company that pulled off the

23.02.2025, 19:21:09 | Engadget
Apple’s M4 MacBook Air could be here in just a few weeks

We may see the M4 MacBook Air as soon as March. In the

23.02.2025, 16:50:21 | Engadget
The secretive X-37B space plane snapped this picture of Earth from orbit

It’s not every day that we get to see a glimpse of what a mysterious space plane is up to in orbit. This week, the US Space Force shared a picture it says was snapped last year by the X-37B, showin

22.02.2025, 22:30:11 | Engadget
An XR game trilogy based on Neon Genesis Evangelion is in the works

South Korean game development studio Pixelity says it’s working on a series of XR games based on Neon Genesis Evangelion, and the first one will be released next year. In an emailed announ

22.02.2025, 22:30:10 | Engadget